#ColdcardBTCExploit

‏‎412.7 ألف‏ من المشاهدات|‏‎279‏ منشور

About ColdcardBTCExploit

The Coldcard hardware wallet incident keeps widening. Galaxy Research estimates stolen funds now exceed 1,000 BTC, around $70M, affecting nearly 1,200 addresses. The flaw traces to a seed-generation defect from firmware 4.0.1 in 2021, mainly hitting the Mk3 model, with some Mk4, Mk5 and Q devices also affected. Coinkite's CEO said he takes full responsibility, shipped an emergency firmware update, and urged users to move funds fast. A five-year-old line of buggy code is cashing out today.

العملات الرقمية ذات الصلة
BTC
‏‎‎-0.93‎%‎‏

ColdcardBTCExploit المنشورات الشائعة

鸭橘子
鸭橘子
🚨 $38M STOLEN FROM $BTC COLD WALLETS — CZ'S SHOCKING REALITY CHECK! ⚡ 🛡️ The $38M Coldcard incident is a brutal reminder that self-custody is not a set-and-forget decision. CZ's assessment cuts straight to the heart of institutional-grade risk thinking: every layer of security you add creates a new vector of failure. 🔍 💡 Diversifying across several wallets reduces single-point exposure, but multiplies the complexity of tracking keys, seed phrases, and recovery paths. Smart money understands that security is an ongoing process, not a one-time product choice. 📊 The real lesson: there is no "100% secure" — only better-managed risk, continuously reassessed. 💬 How do you balance wallet diversification against the operational burden it creates? 👇 ⚠️ Not financial advice. Always manage your risk. 🛡️ 🏷️ #BTC #WalletSecurity #CryptoSecurity #SelfCustody #Crypto
Birdie_OKX
Birdie_OKX
A sobering one for the self-custody crowd. A software bug in Coldcard, a widely trusted Bitcoin hardware wallet, made seed generation predictable enough that attackers swept roughly 594 BTC (about $38M) from around 500 wallets, no phishing, no leaked key, just weak entropy at the source. Your wallet is only as safe as the randomness behind your seed. The uncomfortable takeaway isn't "self-custody is bad," it's that self-custody moves the risk, it doesn't erase it. The same stretch we watched a bridge and an oracle fail, a hardware wallet's key generation did too, all of them the infrastructure around the cryptography rather than the cryptography itself. This will push some users toward ETFs and custodians, a real tradeoff, not a free lunch. Security is a discipline, not a device. Verify your entropy, diversify your risk, assume nothing is bulletproof. NFA. #ColdcardBTCExploit #OKXOrbit
Crypto Crib
Crypto Crib
🚨 COLDCARD WALLET EXPLOIT TOPS $70 MILLION IN LOSSES Over $70M has now been lost to the Coldcard wallet vulnerability, according to Galaxy Research. Nearly 1,200 wallet addresses have reportedly been drained & more than 1,000 BTC has been stolen as the attack continues to escalate.
Katherine smil
Katherine smil
🚨 500 "cold" wallets drained in 25 minutes. 594 BTC gone. Coldcard just confirmed a firmware flaw that let hackers wipe out nearly 500 wallets at once. The twist: it wasn’t phishing. It wasn’t a leaked seed. It was bad randomness. What happened: Instead of using the chip’s true hardware random generator, some Coldcards fell back to predictable inputs: - Chip serial number - System timestamp - Other guessable data A 256-bit private key should be $2^{256}$ possibilities. Unbreakable. But when randomness is weak, the keyspace collapses. Hackers didn’t "crack" keys — they just replayed the generation process and matched on-chain addresses. Find BTC, sweep instantly. That’s why 500 wallets vanished in one coordinated wave. The lesson: Cold safe if the key was born wrong. Being offline doesn’t matter if your private key was predictable from day one. Real security comes down to 4 things: 1. Trusted HRNG for entropy 2. Audited firmware 3. Verifiable, public security 4. Zero predictable inputs in key generation In crypto, security isn’t about hardware. It’s about unpredictability. If randomness fails, your cold wallet is just a hot wallet waiting to be emptied. #SoftPCEStrongDemand #AMZNMissesButRallies #MSFT450BInADay
Xena Warrior
Xena Warrior
🚨 Imagine waking up to find your cold wallet empty... without ever clicking a phishing link. Nearly 500 cold wallets were drained in just 25 minutes, with 594 BTC wiped out. The shocking part? It wasn't phishing. It wasn't a stolen seed phrase. It was bad randomness. Coldcard confirmed a firmware flaw where some devices failed to use the chip's true hardware random number generator (HRNG). Instead, they relied on predictable inputs like: - Chip serial number - System timestamp - Other guessable data A properly generated 256-bit private key has 2²⁵⁶ possible combinations—effectively impossible to brute-force. But when randomness is weak, that massive keyspace collapses. Hackers didn't "crack" private keys. They simply recreated the same predictable key generation process, matched the resulting on-chain addresses, and instantly swept any wallets holding BTC. That's how nearly 500 wallets disappeared in one coordinated attack. The real lesson: A cold wallet isn't automatically secure if the private key was flawed from the moment it was created. Being offline doesn't protect you if your key was predictable from day one. Real security depends on: 1. Trusted HRNG for entropy 2. Audited firmware 3. Verifiable, public security 4. Zero predictable inputs during key generation In crypto, security isn't just about the hardware you buy—it's about the unpredictability behind the keys. If randomness fails, even a cold wallet can become a hot wallet waiting to be emptied. #DailyOrbit
NovaQueen
NovaQueen
🚨 One security failure. Over $40 million in Bitcoin gone. More than $40 million worth of Bitcoin has reportedly been stolen following the Coldcard hardware wallet hack, raising fresh concerns about crypto security. The incident is a reminder that self-custody isn't just about owning a hardware wallet—it's about securing every part of the process, from where you buy the device to how you protect your recovery phrase. Whether you're holding 0.01 BTC or 100 BTC, security should never be an afterthought. As more details emerge, this could become one of the most closely watched hardware wallet incidents in recent years. 👀 Do you think this changes how people will store their Bitcoin going forward? #DailyOrbit
📊Pro Markets Trader
📊Pro Markets Trader
> 🚨 The Cold Hardware Wallet Exploit Incident — What Happened Briefly? 🚨 More than 1,000 $BTC, worth around $63 million, were stolen from hundreds of Coldcard Mk3 hardware wallets within approximately 25 minutes. The number of victims is estimated to be over 500 wallets, and the attacker did not physically hack any device. 😐 The reason? A software vulnerability from 2021 caused the recovery phrase (Seed Phrase) to depend on the device’s startup timing and the speed at which users pressed the buttons, instead of using true randomness. This made guessing recovery phrases significantly easier — a flaw that went unnoticed. The attacker discovered the vulnerability early, precomputed the private keys, then waited until the wallets were funded with Bitcoin. After that, they moved everything out. 🔻 Ledger / Trezor wallets and other devices are not affected by this issue and are currently considered safe. 📊 Follow me for more trading opportunities and daily market analysis.$BTC $ETH
FJ
FJ
The Coldcard situation is a good practice test for migrating BTC into low entropy seed into a new one! You’ll need it for when we go post quantum!
NEXORA_
NEXORA_
🚨BREAKING: More than $38M worth of Bitcoin (594.48 $BTC ) has been stolen from around 500 wallets. Following the incident, Coldcard has urged some users to move their Bitcoin after identifying a vulnerability affecting certain devices. The warning applies to seeds generated on Mk3 wallets running firmware 4.0.1 and later, with some older Mk4, Mk5 and Q firmware also under review. Researchers are investigating the theft, but a direct link between the stolen funds and the Coldcard vulnerability has not been confirmed. If you're using an affected device, it's worth reviewing the latest guidance and checking whether your wallet could be impacted.
DGMD.6529
DGMD.6529
i don't think the ripple effects of the bitcoin hack have even started yet. there's a saying that is mostly true, 'the bottom is in when you run out of sellers, not when the buyers step in'. unfortunately what i think the bitcoin hack did was 2 fold: - it unlocked a new class of sellers that perfectly fine hodl'ing before... long term holders with self-custodied assets... holders that don't like the idea of centralized holding but now feel uneasy with how they've been holding for years.. not great. - continued to put dings in the bitcoin narrative as a pristine SoV. my personal thoughts around bitcoin is that it could go up at some point, but will likely find a range, not a new high until it becomes one of the following: daily transactional money or a pristine SoV. I have my doubts that it ever becomes daily transactional money... I do think it eventually becomes a pristine SoV.. but not until there are clear answers for quantum, ai-assisted hacks, tail end security answered, etc. no one is paying 300k per bitcoin when people are getting their entire balance wiped by hacks while doing nothing and following what everyone has always told them to do for safe storage